CVE-2013-10065
Sysax Multi Server vulnerability analysis and mitigation

Overview

CVE-2013-10065 is a denial-of-service (DoS) vulnerability in Sysax Multi-Server version 6.10 affecting its SSH daemon. A specially crafted SSH key exchange packet containing a non-standard byte (\x28) in place of the expected SSH protocol delimiter can trigger a crash in the SSH service, resulting in complete loss of availability. The vulnerability was originally discovered in 2013 but formally assigned a CVE and published in August 2025. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Red Hat CVE, VulnCheck Advisory).

Technical details

The root cause is classified as CWE-248 (Uncaught Exception), where the SSH daemon in Sysax Multi-Server 6.10 fails to properly handle malformed key exchange data during the SSH handshake process. When a client sends a key exchange packet with a non-standard byte (0x28) substituted for the expected SSH protocol delimiter, the daemon does not catch the resulting exception and crashes. The attack requires no authentication, no user interaction, and is remotely exploitable over the network with low complexity. A public technical write-up and a Metasploit auxiliary module are available detailing the exploitation mechanics (Matt Andreko Blog, Metasploit Module).

Impact

Successful exploitation causes the SSH daemon in Sysax Multi-Server 6.10 to crash, resulting in a complete loss of SSH service availability. This disrupts remote access and management capabilities for the affected server. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Repeated exploitation could keep the SSH service persistently unavailable, effectively locking administrators out of remote management (Red Hat CVE, VulnCheck Advisory).

Exploitability

Public proof-of-concept exploit code is available in two forms: a researcher blog post from 2013 and a Metasploit auxiliary module (auxiliary/dos/windows/ssh/sysax_sshd_kexchange), making exploitation straightforward for any attacker with basic tooling (Metasploit Module, Matt Andreko Blog). No authentication is required, and the attack can be launched remotely with no user interaction. There is currently no evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, indicating low probability of near-term exploitation (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing hosts running Sysax Multi-Server 6.10 using network scanners (e.g., Shodan, Nmap) by targeting the default SSH port (typically TCP 22) and fingerprinting the SSH banner.
  2. Set up Metasploit: Load the auxiliary module auxiliary/dos/windows/ssh/sysax_sshd_kexchange in the Metasploit Framework.
  3. Configure the module: Set the RHOSTS parameter to the target IP address and RPORT to the SSH service port.
  4. Send malformed key exchange packet: Execute the module, which sends a specially crafted SSH key exchange packet containing the non-standard byte 0x28 in place of the expected SSH protocol delimiter.
  5. Trigger crash: The SSH daemon fails to handle the malformed packet, an uncaught exception occurs, and the SSH service crashes — resulting in denial of service (Metasploit Module, Matt Andreko Blog).

Indicators of compromise

  • Network: Unexpected or repeated TCP connection attempts to the SSH port (default 22) from external or untrusted IP addresses; connections that terminate abruptly during the key exchange phase without completing authentication.
  • Logs: SSH daemon logs showing errors or exceptions during key exchange negotiation; service crash or restart events logged in the Windows Event Log or Sysax application logs immediately following inbound SSH connections.
  • Process: Unexpected termination or restart of the Sysax Multi-Server SSH daemon process; monitoring tools or service watchdogs triggering alerts on SSH service unavailability.

Mitigation and workarounds

No specific vendor patch information is publicly available for this vulnerability. The following mitigations are recommended: restrict SSH access to trusted IP ranges using firewall rules; implement network-level filtering to block or rate-limit inbound SSH connections from untrusted sources; deploy an intrusion detection/prevention system (IDS/IPS) capable of detecting malformed SSH key exchange packets; monitor SSH service logs for anomalous connection patterns; and consider migrating to a newer, actively maintained SSH server solution if an updated version of Sysax Multi-Server is not available (VulnCheck Advisory, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related Sysax Multi Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2012-10060CRITICAL9.3
  • Sysax Multi Server logoSysax Multi Server
  • cpe:2.3:a:sysax:multi_server
NoYesAug 13, 2025
CVE-2013-10065HIGH8.7
  • Sysax Multi Server logoSysax Multi Server
  • cpe:2.3:a:sysax:multi_server
NoYesAug 05, 2025
CVE-2024-53458HIGH7.5
  • Sysax Multi Server logoSysax Multi Server
  • cpe:2.3:a:sysax:multi_server
NoNoMar 05, 2025
CVE-2024-53459MEDIUM5.4
  • Sysax Multi Server logoSysax Multi Server
  • cpe:2.3:a:sysax:multi_server
NoNoDec 02, 2024
CVE-2023-54337MEDIUM5.1
  • Sysax Multi Server logoSysax Multi Server
  • cpe:2.3:a:sysax:multi_server
NoNoJan 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management